Privacy Notice
How Too Sweet Logistics Limited collects, uses and protects personal data across our website, customer portal, driver workspace and Corporate API. Last updated 1 September 2026.
1. Who is responsible for your data
Too Sweet Logistics Limited (company number 17368275, registered office 3 Cherry Orchard Court, Leicester, LE2 9DN) is the controller for the personal data described here under UK GDPR. Contact us at info@toosweetlogistics.co.uk or 07367 417240.
Where a corporate customer instructs us to carry goods and supplies us with recipient details, that customer is the controller of the data it supplies and we act as controller for the carriage records we then create.
2. Who this notice covers
- customers and account holders
- prospective customers who request a quote or submit an enquiry
- corporate and business contacts, including named account and billing contacts
- drivers, including employed, self-employed and subcontracted drivers
- collection contacts and delivery recipients
- portal, workspace and Corporate API users
3. What we process
- Names, company names and job titles
- Email addresses and telephone numbers
- Collection and delivery addresses, postcodes, access and parking instructions, and saved address book entries
- Quote details — postcodes, service level, load type, weight, dimensions, stops, dates and notes
- Bookings and jobs, including status history, timeline events and operational notes
- Live tracking and delivery status information shown to the customer
- Driver device GPS/location data, captured only while a driver is on duty with location sharing switched on during a job
- Proof of delivery — timestamped photographs, recipient names, captured signature images, arrival and completion timestamps, and (where available) the device location at the point of delivery, including authorised unattended deliveries
- Invoices, payment status, refunds and payment reference data
- Customer-service records — enquiries, business enquiry submissions, complaints, claims and correspondence
- Account and authentication data, including sign-in events, roles and two-factor authentication state
- Audit and security logs — actions taken in the platform, IP address, request metadata and rate-limiting records
- Corporate account and API data — account and key metadata (never the key itself, which is stored only as a hash), submitted manifests, API request logs, idempotency records and webhook delivery logs
- Driver compliance information — licence, CPC, medical and right-to-work expiry dates, availability and assigned vehicle
4. Why we process it, and our lawful bases
- Quotes, bookings and deliveries — performance of a contract, or steps at your request before entering a contract.
- Tracking, proof of delivery and job records — contract performance and our legitimate interests in evidencing completed work and resolving disputes.
- Recipient contact details — legitimate interests in completing the delivery our customer instructed.
- Invoicing, payments, refunds and accounting — contract performance and legal obligation.
- Customer service, complaints and claims — contract performance and legitimate interests in handling claims and defending legal claims.
- Account security, audit logging, rate limiting and fraud prevention — legitimate interests in protecting the platform and customer data, and legal obligation.
- Corporate API access — contract performance and legitimate interests in securing and metering programmatic access.
- Driver compliance records — legal obligation and legitimate interests in operating lawfully and safely.
- Driver GPS while sharing is enabled — legitimate interests in live dispatch, driver safety and accurate customer updates.
- Service emails (quote, booking, delivery, POD, invoice, payment and account notifications) — contract performance.
5. Processors and services we use
These providers process data on our behalf under contract:
- Supabase — hosted database, authentication and file storage (including POD photographs and signatures).
- Lovable / Cloudflare — application hosting, delivery and edge security.
- Stripe — card and wallet payment processing and refunds. Stripe receives card details directly; we hold only payment status and reference data.
- Resend — transactional email delivery (quotes, bookings, delivery updates, POD, invoices, receipts and account emails), including delivery logs.
- Google Maps Platform — address autocomplete, geocoding, distance and route calculation for pricing, dispatch and mapping.
We may also share information with subcontracted carriers performing a delivery, with our insurers and loss adjusters when handling a claim, with professional advisers, and with authorities where required by law or to establish or defend legal claims. We do not sell personal data and do not use it for third-party marketing.
6. Public tracking and privacy safeguards
Our public tracking page requires a matching job number and delivery postcode and shows delivery status only. It never exposes POD photographs, GPS coordinates, storage URLs, driver personal information, recipient or customer personal details, or internal notes. Full permitted POD evidence is available only to signed-in customers and authorised staff, and through authenticated Corporate API access scoped to that account.
7. International transfers
Some providers may process data outside the UK. Where that happens, transfers rely on safeguards recognised by UK data protection law, such as UK adequacy regulations or the UK International Data Transfer Agreement or Addendum.
8. How long we keep it
- Quote enquiries and business enquiries that do not become bookings — kept only as long as needed to follow up and evidence pricing.
- Job, tracking and proof-of-delivery records — kept for the period needed to handle claims, disputes and service history.
- Invoices, payments and accounting records — kept for the period required by UK tax and company law.
- Driver GPS points and operational telemetry — kept only for the period needed for dispatch, service evidence and safety review.
- Audit, security, API request and webhook logs — kept for the period needed for security investigation and accountability.
9. Security
Access is role-based and enforced at the database level, administrator access requires two-factor step-up authentication, API keys are stored only as hashes, POD evidence is served through short-lived signed links, and privileged actions are recorded in an immutable audit log.
10. Your rights
Under UK GDPR you have the right to be informed; to access your data; to have inaccurate data corrected; to request erasure; to restrict processing; to object to processing based on legitimate interests, including profiling; to data portability where applicable; and to withdraw consent where processing is based on consent. We do not carry out automated decision-making producing legal or similarly significant effects.
To exercise a right, email info@toosweetlogistics.co.uk. We may need to verify your identity, and we respond within one month unless the request is complex, in which case we will tell you.
11. Cookies and browser storage
See our Cookie & Storage Policy.
12. Complaints
If you are unhappy with how we have handled your data, please contact us first. You also have the right to complain to the Information Commissioner's Office (ICO), Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF, telephone 0303 123 1113, ico.org.uk.
Contact us
Too Sweet Logistics Limited
3 Cherry Orchard Court, Leicester, LE2 9DN
info@toosweetlogistics.co.uk · 07367 417240
